# Running in the background

The app is designed to be invisible once set up.

## The system tray

Closing the window hides the app to the tray rather than quitting it. The tray menu has
**Show Sentilai Endpoint** and **Quit**; left-clicking the icon reopens the window.

## The connectivity badge

If a host the app needs is unreachable, the tray icon gains an amber badge and the window
shows a banner naming the host. It keeps retrying — this is usually a VPN that has just
come up, or a firewall rule that has not been widened yet.

Your network team may need the hostnames; see [Hostnames and firewall rules](/books/network-and-deployment/page/hostnames-and-firewall-rules).

## Automatic updates

The app checks for updates, verifies the download's signature before installing it, and
replaces itself. Verified on macOS; on Windows the updater ships but has not yet been
proven end to end, so treat Windows updates as manual for now.

## What it does periodically

- **Adapter drift check** — is each governed tool still pointing at the Gateway? A tool
  that has drifted is re-governed if automatic governing is on, and either way the console
  shows the device as **Non-compliant**.
- **Log request poll** — roughly every two minutes, so that an admin's request for logs
  is fulfilled promptly.
- **Posture scan** — read-only inspection of your AI tools' own autonomy settings, sent
  to the console as posture findings. It reads configuration, never prompts or code.